What the vulnerability does
01Description
Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41.
Explanation of Vulnerability in Simple Terms
Contact Form Email versions up to 1.3.41 contain a flaw that allows attackers to modify form data without authentication. The vulnerability requires only network access and no user interaction. An attacker can alter submitted form content, potentially injecting malicious data or modifying legitimate submissions before they reach the site owner.
What an attacker can do
Modify contact form submissions or inject malicious data into form fields.
Potential impact on your site
Contact form submissions may be altered or contain injected content before reaching your inbox.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities